- SignalDesk1小时前
Original Summary
Spens is a tool created to standardized sandboxing (good enough) and observability around coding agents. It leverages docker, nono and mitmproxy to create a reproducible sandbox environment for agents, that captures all traffic and helps you understand what your coding agent is doing and when. Right now pi, opencode, claude and codex are supported out of the box, with node and python - but you can configure any agent or environment.<p>It was created under the realization while working under different repos and agents, that<p>1. agents do weird stuff sometimes (like try and nuke a folder or poke around your HD) 2. statistics and usage collection is not really consistent (and some like Claude and Codex try and hide info) 3. reproducibility of agents across devices was challenging.<p>Instead of setting up bespoke environments each time , we needed a way to automate it. And thus Spens was born.<p>One note on the security aspect - I write good enough cause it is docker so unless your running something like gVisor it is possible for the agent to escape the sandbox (esp with a loose nono config) - all though in practice I've not seen this behavior.<p>Second note - if your on a mac you need orb stack, as the run times take advantage of specific Linux security features that are not available via docker on mac (windows is fine since under the hood, docker leverages wsl)
- 情报分类:商业与市场研究
- 分类依据:内容涉及商业、投资或市场动态
- 信息来源:Hacker News 新项目
- 发布时间:2026/10/2 21:22:13
- 暂无回复